Security used to be about fences and gates. Today those things are largely symbolic: apps live in public clouds, employees work from coffee shops, and third-party code runs inside your stack. The real fight is about two…
From perimeter to identity: what changed and why it matters
Traditional defenses assumed protected networks and trusted users inside them. That model broke years ago as cloud and SaaS adoption accelerated. Applications aren’t sitting behind a corporate firewall; they’re served from multi-tenant clouds, accessed through single-sign-on systems, and integrated via APIs. In this world, the single most valuable control plane is identity — who is requesting access, from where, and under what context.
Zero trust is the concise expression of that shift: verify every request rather than implicitly trusting a device or network zone. But zero trust is a philosophy, not a product. To operationalize it you need granular identity signals (user, device, session) and continuous validation, which in turn requires rich telemetry. Without those signals an organization can’t answer basic questions during an attack — whether a login was legitimate, whether an action broke policy, or whether lateral movement is happening.
Telemetry: the raw material defenders need
Telemetry means logs, traces, and metrics from endpoints, identity providers, cloud services, network devices, SaaS apps, and security controls. Each data stream is a slice of truth: endpoint logs show process activity, cloud logs show API calls, and identity providers record authentication events. Correlating those slices is how incidents are detected and investigated.
But telemetry is messy. It arrives in different formats, at different speeds, and with varying retention and fidelity. High-cardinality data (detailed records about sessions or queries) is expensive to store and analyze. That’s why many breaches aren’t detected until well after an attacker established persistence: organizations either don’t collect the right data, or they can’t stitch it together fast enough.
How modern security stacks stitch identity and telemetry together
Recent product evolution focuses on unifying identity signals with broad telemetry ingestion. Extended detection and response (XDR) approaches try to pull data from endpoints, networks, and cloud services into a single analytics layer. Meanwhile, identity-centric controls — identity governance, conditional access, and privileged access management — enforce policies based on contextual signals.
What makes some newer tools different is API-native integrations and analytics built for cloud-scale data. Rather than forwarding all telemetry into a single lake, solutions increasingly offer targeted ingestion, enrichment (for example attaching user context to an event), and threat scoring. That reduces noise for security teams and makes automated blocking decisions safer. Another practical trend is the rise of SaaS posture and supply-chain security tools that monitor third-party apps and CI/CD pipelines, because attackers often enter through those weakest links.
Where this dynamic affects budgets, vendors, and risk
Executives and boards are reacting to high-profile ransomware and supply-chain incidents by demanding better detection and faster response. That drives four observable shifts: more spend on identity and access controls; allocations to telemetry platforms and analytics; movement toward cloud-native, subscription-delivered security; and a tighter relationship between security teams and cloud/SaaS providers for telemetry access.
For organizations, it matters how much telemetry a vendor can ingest without prohibitive costs, how quickly alerts can be triaged, and whether identity context is baked into detection rules. Vendors that can normalize diverse signals and present a concise, context-rich view to human analysts — or automate trustworthy responses — will be in demand. At the same time, regulators and insurers are asking for demonstrable controls around identity and monitoring, which influences procurement and tooling choices.
The Bottom Line
As cloud, SaaS, and remote work remain dominant, security is moving from perimeter defenses to identity and telemetry as the primary levers. Practical security means collecting the right signals, enriching them with identity context, and using analytics to convert raw data into timely, accurate action. That shift is reshaping vendor architecture, buyer priorities, and how organizations allocate security budgets — understanding it helps explain the winners and the choices companies are making today.
Want ideas like this every week?
Join the free Breakout Brief — the setups, sectors and signals we are watching.